Authentication Bypass in OpenStack Zaqar by OpenStack Foundation
CVE-2026-66139

4.8MEDIUM

Key Information:

Vendor

Openstack

Status
Vendor
CVE Published:
24 July 2026

What is CVE-2026-66139?

An authentication bypass vulnerability exists in OpenStack Zaqar versions up to 22.0.0, allowing attackers to gain unauthorized access by exploiting an EXTRA-SPEC header if a known UUID is provided. This flaw could potentially allow malicious entities to bypass authentication mechanisms, posing significant risks to the security of the OpenStack services reliant on Zaqar.

Affected Version(s)

Zaqar 12.0.0 < 20.1.1

Zaqar 21.0.0

Zaqar 22.0.0

References

CVSS V3.1

Score:
4.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.